top of page
perceptive_background_267k.jpg

A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGe…

Published:

31 August 2026 at 00:00:00

Alert date:

31 August 2026 at 23:17:03

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Zero-Day Vulnerabilities

A vulnerability has been identified in Soarkey StudentManagement (学生信息管理系统) affecting versions up to commit e08f7f1d5015af407aa4cca0ada3dea189b4937e. The flaw resides in the AdminDao.doGet function within the file code/src/service/AdminDao.java, part of the Administrative Servlet component. By manipulating the 'action' argument, an attacker can achieve authorization bypass remotely. A public exploit is already available, increasing the risk of active exploitation. The project maintainer was notified via a GitHub issue report but has not responded. This is a remotely exploitable, publicly disclosed vulnerability with no known patch or vendor acknowledgment at the time of reporting.

Technical details

Mitigation steps:

Affected products:

Soarkey StudentManagement
学生信息管理系统

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page